1. Data Processing Agreement

Legal

Data Processing Agreement

Last updated: September 6, 2026

Data Processing Agreement — v1, under final legal review.

This Data Processing Agreement ("DPA") is entered into under Article 28(3) of Regulation (EU) 2016/679 ("GDPR") between:

Huldin Group AB, org. nr 559341-0672, Brantvägen 3, 133 42 Saltsjöbaden, Sweden ("YachtMaster", "we", the Processor), and

the customer accepting the YachtMaster Terms of Service ("you", the Controller).

This DPA forms an integral part of the Terms of Service and is accepted at the same time as them. It applies for as long as we process personal data on your behalf. Where this DPA conflicts with the Terms of Service on a data protection matter, this DPA prevails.

1. Roles of the Parties

You are the controller and we are your processor in respect of personal data that you or your users enter into, generate in, or upload to the Service — for example data about your customers, boat owners, vessel contacts and your own employees ("Customer Personal Data").

We are an independent controller in respect of the personal data we process for our own purposes — your account and billing details, authentication data, and technical logs used to secure and operate the Service. That processing is described in our Privacy Policy and is not governed by this DPA.

You are responsible for establishing a lawful basis under Article 6 GDPR for the Customer Personal Data you place in the Service, for the accuracy of that data, and for providing the information required by Articles 13 and 14 to the individuals concerned.

2. Subject Matter, Duration, Nature and Purpose

Subject matter and purpose: our provision of the Service to you under the Terms of Service — managing service requests, maintenance scheduling, customer and vessel records, quotations, contracts, invoicing and related communications.

Nature of processing: collection, recording, organisation, structuring, storage, retrieval, consultation, use, transmission, backup, restriction and erasure, carried out by automated means.

Duration: for the term of your subscription, plus the post-termination export period set out in the Terms of Service, after which section 10 of this DPA applies.

3. Categories of Data Subjects

  • Your customers and prospective customers, and their representatives
  • Boat and vessel owners, and their contacts
  • Your employees and contractors who use the Service
  • Suppliers, subcontractors and other business contacts you record in the Service

4. Types of Personal Data

  • Identity and contact data — name, company, role, address, email, telephone
  • Vessel-related data where it relates to an identifiable person — ownership, berth, service and maintenance history
  • Transactional data — quotations, orders, contracts, invoices, payment status
  • Communications — messages, notes and documents exchanged through the Service
  • User account data for your users — username, role, permissions, activity logs

The Service is not designed for, and you must not use it to process, special categories of personal data under Article 9 GDPR or data relating to criminal convictions under Article 10.

5. Our Obligations

5.1 Documented Instructions

We process Customer Personal Data only on your documented instructions, which comprise the Terms of Service, this DPA, and your configuration and use of the Service, including with regard to transfers to a third country. If we are required by EU or Swedish law to process for another purpose, we will inform you before doing so unless that law prohibits it. We will inform you if, in our opinion, an instruction infringes the GDPR or other data protection law.

5.2 Confidentiality

We ensure that persons authorised to process Customer Personal Data are bound by an obligation of confidentiality, whether contractual or statutory, and that access is limited to those who need it to perform their duties.

5.3 Security

We implement appropriate technical and organisational measures under Article 32 GDPR, taking account of the state of the art, cost, and the nature, scope, context and purposes of processing. These currently include:

  • Encryption of data in transit using TLS
  • Encryption at rest for stored data and backups
  • Passwords hashed using Argon2; short-lived session tokens
  • Role-based access controls and logical separation of customer data
  • Least-privilege administrative access, with access reviewed periodically
  • Regular backups with tested restore procedures
  • Logging of access to and changes in customer records

We may update these measures over time, provided the level of security is not reduced.

5.4 Assistance with Data Subject Rights

Taking into account the nature of the processing, we assist you by appropriate technical and organisational measures, insofar as possible, in fulfilling your obligation to respond to requests under Chapter III GDPR — access, rectification, erasure, restriction, portability and objection. The Service provides functionality to search, export, correct and delete records. Where you need further assistance, contact us and we will respond without undue delay and in any event in time for you to meet your statutory deadline.

If a data subject contacts us directly regarding Customer Personal Data, we will not respond substantively but will refer them to you and inform you without undue delay.

5.5 Assistance with Articles 32–36

We assist you in ensuring compliance with the obligations in Articles 32 to 36 GDPR — security, breach notification, data protection impact assessments and prior consultation — taking into account the nature of processing and the information available to us.

5.6 Personal Data Breach

We notify you without undue delay, and in any event within forty-eight (48) hours of becoming aware of a personal data breach affecting Customer Personal Data. The notification will describe, as far as known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. We will provide further information as it becomes available, so that you can meet your obligations under Articles 33 and 34.

5.7 Records and Audits

We make available to you the information necessary to demonstrate compliance with Article 28 GDPR. On reasonable written notice of at least thirty (30) days, and no more than once in any twelve (12) month period unless a supervisory authority requires otherwise or following a personal data breach, we allow for and contribute to an audit, including an inspection, conducted by you or an independent auditor you appoint who is not a competitor of ours and who is bound by confidentiality. Audits take place during normal business hours, must not unreasonably disrupt our operations, and are at your cost. We may satisfy an audit request by providing an up-to-date third-party certification or audit report where one adequately addresses your request.

6. Sub-processors

You give us general written authorisation to engage sub-processors for the provision of the Service. We impose on each sub-processor data protection obligations that are no less protective than those in this DPA, and we remain fully liable to you for the performance of each sub-processor's obligations.

Our current sub-processors are:

Sub-processorPurposeLocation
Amazon Web Services EMEA SARLHosting, database, file storage, backupsEU (Stockholm, eu-north-1)
Amazon Web Services EMEA SARL (SES)Transactional email deliveryEU (Stockholm, eu-north-1)
Amazon Web Services EMEA SARL (CloudFront)Content delivery for files and documentsGlobal edge network
Cloudflare, Inc.Website delivery, DNS, bot protectionGlobal edge network
Stripe Payments Europe, Ltd.Subscription billing and payment processingEU / USA
Google Ireland LimitedAddress lookup and text translation featuresEU / USA

6.1 Integrations You Enable

Some features transmit Customer Personal Data to a third party with whom you hold the account and the contract. You enable these yourself and supply your own credentials; we do not select the provider for you. Where you enable one, that provider acts on your instructions and not as our sub-processor, and you are responsible for your own agreement with it, for your own lawful basis, and for your own assessment of any transfer outside the EU/EEA.

  • Accounting — Fortnox, Netvisor. Transmits customer, invoice and sales records.
  • E-signing — Visma Sign. Transmits document content together with the name, email address and signing events of each signatory.
  • AI assistant — Anthropic, Google or xAI, whichever you select. This is off unless you switch it on and enter your own API key. While it is on, your users' prompts and the content of the records the assistant is asked about are transmitted to the provider you chose. Some of these providers are established outside the EU/EEA. We do not use this data for our own purposes and we do not train models on it; what the provider does with it is governed by your agreement with them.

You can see and change which of these are active in Settings at any time. Switching one off stops further transmission but does not recall data already sent — for that, contact the provider directly.

Changes. We will notify you by email or through the Service at least thirty (30) days before adding or replacing a sub-processor. You may object on reasonable data protection grounds within that period. If we cannot resolve your objection, you may terminate your subscription with effect from the date the change takes effect and receive a refund of prepaid fees covering the period after termination.

7. Personnel and Partners

Where a sales partner, reseller or other representative acts on our behalf and is given access to any environment containing Customer Personal Data, they are engaged as our sub-processor, are bound by written obligations equivalent to this DPA, and are listed under section 6. Our sales partners are given access to prospect and sales records only, and are not granted standing access to live customer environments.

8. International Transfers

Customer Personal Data is stored within the EU/EEA. Where a sub-processor listed in section 6 processes data outside the EU/EEA, that transfer is made on the basis of the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914) or another valid transfer mechanism under Chapter V GDPR, supported by a transfer impact assessment and supplementary measures where required. We will not transfer Customer Personal Data outside the EU/EEA other than as described in section 6 without informing you first.

9. Your Obligations

  • Ensure you have a lawful basis for the Customer Personal Data you process through the Service, and provide the required transparency information to data subjects
  • Issue instructions that comply with data protection law
  • Configure the Service, and manage your users' access rights, appropriately for the data you hold
  • Not upload special categories of personal data or criminal offence data to the Service
  • Keep account credentials secure and notify us promptly of any suspected unauthorised access

10. Deletion and Return

On termination of the Service, you may export Customer Personal Data during the period stated in the Terms of Service. At the end of that period we delete Customer Personal Data, or return it if you so request in writing before the period expires. Backup copies are deleted in the ordinary course of our backup rotation, and until then remain subject to this DPA. We may retain data where EU or Swedish law requires it — for example accounting records under the Swedish Accounting Act (bokföringslagen 1999:1078) — and will process it only for that purpose.

11. Liability

Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service, except where those limitations are not permitted by Article 82 GDPR or other mandatory law.

12. Changes to this DPA

We may update this DPA where necessary to reflect changes in law, guidance from supervisory authorities, or changes to the Service. Material changes are notified in accordance with the change procedure in the Terms of Service.

13. Governing Law

This DPA is governed by the substantive laws of Sweden and is subject to the dispute resolution provisions of the Terms of Service.

14. Contact

For data protection questions or to exercise any right under this DPA:
Huldin Group AB, org. nr 559341-0672
Brantvägen 3, 133 42 Saltsjöbaden, Sweden
contact@yachtmaster.cloud

enfisv